CWE Database
/

CWE-615

Back to CWE list

CWE-615

Inclusion of Sensitive Information in Source Code Comments

Variant
Incomplete

Description

While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.

An attacker who finds these comments can map the application's structure and files, expose hidden parts of the site, and study the fragments of code to reverse engineer the application, which may help develop further attacks against the site.

Related Weaknesses

Common Consequences

Scope

Confidentiality

Impact

Read Application Data

Potential Mitigations

Distribution

Remove comments which have sensitive information about the design/implementation of the application. Some of the comments may be exposed to the user and affect the security posture of the application.

CVE-2007-6197

Version numbers and internal hostnames leaked in HTML comments.

CVE-2007-4072

CMS places full pathname of server in HTML comment.

CVE-2009-2431

blog software leaks real username in HTML comment.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now